TI Mindmap HUB
Threat Intelligence Report

Popular node-ipc npm Package Infected with Credential Stealer

๐Ÿ“… May 14, 2026 ๐Ÿ“ฐ socket.dev ๐Ÿ” 0 CVE(s) referenced

Malicious versions of the widely used node-ipc npm package were published via a compromised maintainer account, enabling highly stealthy credential and configuration theft from developer and CI environments through obfuscated code that exfiltrates sensitive data using DNS TXT queries.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle